Zyxel We4600-00 Firmware vulnerabilities
3 known vulnerabilities affecting zyxel/we4600-00_firmware.
Total CVEs
3
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
HIGH2MEDIUM1
Vulnerabilities
Page 1 of 1
CVE-2025-13943P2HIGHCVSS 8.8fixed in 6.70\(ackt.0\)c02026-02-24
CVE-2025-13943 [HIGH] CWE-78 CVE-2025-13943: A post-authentication command injection vulnerability in the log file download function of the Zyxel
A post-authentication command injection vulnerability in the log file download function of the Zyxel EX3301-T0 firmware versions through 5.50(ABVY.7)C0 could allow an authenticated attacker to execute operating system (OS) commands on an affected device.
nvd
CVE-2026-1460P3HIGHCVSS 7.2fixed in 6.70\(ackt.1\)c02026-04-28
CVE-2026-1460 [HIGH] CWE-78 CVE-2026-1460: A post-authentication command injection vulnerability in the “DomainName” parameter of the DHCP conf
A post-authentication command injection vulnerability in the “DomainName” parameter of the DHCP configuration file in Zyxel DX3301-T0 and EX3301-T0 firmware versions through 5.50(ABVY.7.1)C0 could allow an authenticated attacker with administrator privileges to execute OS commands on an affected device.
nvd
CVE-2026-0711P3MEDIUMCVSS 6.8fixed in 6.70\(ackt.1\)c02026-04-28
CVE-2026-0711 [MEDIUM] CWE-78 CVE-2026-0711: A post-authentication command injection vulnerability in the EasyMesh-related APIs of Zyxel DX3300-T
A post-authentication command injection vulnerability in the EasyMesh-related APIs of Zyxel DX3300-T0 firmware versions through 5.50(ABVY.7.1)C0 could allow an authenticated, adjacent attacker with administrator privileges to execute OS commands on an affected device.
nvd